Recent DoS attacks on Minetest servers

Post Reply
rarkenin
Member
Posts: 668
Joined: Tue Nov 20, 2012 20:48

Recent DoS attacks on Minetest servers

by rarkenin » Post

Sadly, there was a series of DoS/flood attacks on Minetest servers. I have found that this was caused by hexafraction, using my public WiFi. This service has since been taken down. While the originating IPs do correspond to the IPs I use(plural as dynamic), I cannot, and will not take responsibility of hexafraction. I am not his police, nor am I the police of the Minetest community. Please do not direct ANY inquiries about this toward me; direct them toward the person truly responsible, hexafraction.

Also, pardon my acidic behavior in IRC when I was requested to deal with the situation. It is generally irritating to arrive and find people seeking you for the actions of others.

Again, I'm not going to answer for hex. I am not his secretary. Don't ask me about it, unless you are trying to work with me on deblacklisting the IP address that I am allocated. If I am deblacklisted, I will work with hex to ensure this does not happen again. At the moment, I am passively standing by.

I quit a while ago. I'm not dealing with your drama.
Last edited by rarkenin on Wed May 22, 2013 01:28, edited 1 time in total.
Admin pro tempore on 0gb.us:30000. Ask me if you have a problem, or just want help.
This is a signature virus. Add me to your signature so that I can multiply.
Now working on my own clone, Mosstest.
I guess I'm back for some time.

User avatar
VanessaE
Moderator
Posts: 4655
Joined: Sun Apr 01, 2012 12:38
GitHub: VanessaE
IRC: VanessaE
In-game: VanessaE
Location: Western NC
Contact:

by VanessaE » Post

Although you are not personally responsible for the actions of someone else, because you opened your WiFi connection to others, and the IP through which your connection is routed is based in the US, you are legally responsible for those actions. Stupid, I know, but that's the state of things right now.

No sane person expects you to answer for hex or anyone else who used your WiFi. The most anyone here could reasonably expect is for you to do exactly what you did - find the cause and deal with it (by closing off your WiFi in this case).

As for "our drama", just as you are not (or rather, should not be) responsible for hex's actions, neither are we. We as a community are no more responsible for any one user's actions than we are for the severe weather that ripped up the US midwest in the past couple of days. If someone wants to avoid drama, they'd best avoid starting it in the first place.

No one is forcing those people (yourself included) to take the actions they've been taking. Indeed, it is all these ragequitters who are at fault, not us (beyond whatever faults each individual in this community already has).
You might like some of my stuff: Plantlife ~ More Trees ~ Home Decor ~ Pipeworks ~ HDX Textures (64-512px)

rarkenin
Member
Posts: 668
Joined: Tue Nov 20, 2012 20:48

by rarkenin » Post

I have taken all reasonable action possible on my side. The WiFi link has been taken down(it DID have an on-connect disclaimer powered by a small webserver before), and I am working personally with hex to figure out the whys(seems to be to prove a point that MT is a "security failure", the hows(AFAIK a Java program that sent TOCLIENT_INITs and TOCLIENT_INIT2's), and other details. I'd appreciate it if after a week or so, my IPs were removed from the blacklists that I know are on your(vanessaE) server, and the other servers which were targeted. Thank you.
Last edited by rarkenin on Wed May 22, 2013 10:36, edited 1 time in total.
Admin pro tempore on 0gb.us:30000. Ask me if you have a problem, or just want help.
This is a signature virus. Add me to your signature so that I can multiply.
Now working on my own clone, Mosstest.
I guess I'm back for some time.

User avatar
PilzAdam
Member
Posts: 4026
Joined: Fri Jul 20, 2012 16:19
GitHub: PilzAdam
IRC: PilzAdam
Location: Germany

by PilzAdam » Post

Sorry, but I dont believe you.
Do you have a link to the IRC logs?

User avatar
LandMine
Member
Posts: 312
Joined: Tue May 01, 2012 16:44
Location: Mexico City
Contact:

by LandMine » Post

id say call the cops and let them handle it....let him tell them the story of his imaginary friend to them :D......Any ip you blacklisted is obviously his real ip. Still i dunno how serious minor DDosing is in US
List Of My Creative Servers - http://planetminetest.com
The Walls - PvP Map - http://minetest.net/forum/viewtopic.php?id=2906

rarkenin
Member
Posts: 668
Joined: Tue Nov 20, 2012 20:48

by rarkenin » Post

After thinking the situation over for some time, I feel as if the proper thing for me to do as the WiFI operator is to apologize for the damage and technical issues as a result of the attack. However, as I am NOT the originator, I do NOT take any moral obligation/responsibility for this attack. Again, I apologize to the community of Minetest for not quickly acting on the problem or working with the community in a fully constructive manner to resolve the issue. My annoyance in #minetest after being notified was unjust and unnecessary.

Thank you. Do not deblacklist me for the time being.
Admin pro tempore on 0gb.us:30000. Ask me if you have a problem, or just want help.
This is a signature virus. Add me to your signature so that I can multiply.
Now working on my own clone, Mosstest.
I guess I'm back for some time.

tinoesroho
Member
Posts: 570
Joined: Fri Feb 17, 2012 21:55
Location: Canada

by tinoesroho » Post

I don't know whether to punch hex or shake his hand. He made it impossible for me to play on the uplink server, but did point out flaws in the system. I do wish he'd simply warned ahead of time and made the vulnerability public so we could fix it rather than just DOSing, but, can't have an omlette without breaking a few eggs.
We are what we create.

I tinker and occasionally make (lousy) mods. Currently building an MMO subgame and updating mods. Pirate Party of Canada member. Sporadic author. 21 years old.

My github:
https://github.com/tinoesroho/

rarkenin
Member
Posts: 668
Joined: Tue Nov 20, 2012 20:48

by rarkenin » Post

tinoesroho wrote:I don't know whether to punch hex or shake his hand. He made it impossible for me to play on the uplink server, but did point out flaws in the system. I do wish he'd simply warned ahead of time and made the vulnerability public so we could fix it rather than just DOSing, but, can't have an omlette without breaking a few eggs.
I've personally (figuratively, of course) done both. I personally think that we put this incident behind ourselves, and work on fixing the issues brought up. Perhaps limiting logins or implementing some form of proof-of-work to login would be good.

As I've mentioned, both of us have recently experienced a loss of a friend, and the stress apparently caused hex to break down. We'll be moving on ourselves.
Last edited by rarkenin on Fri May 24, 2013 21:36, edited 1 time in total.
Admin pro tempore on 0gb.us:30000. Ask me if you have a problem, or just want help.
This is a signature virus. Add me to your signature so that I can multiply.
Now working on my own clone, Mosstest.
I guess I'm back for some time.

Post Reply

Who is online

Users browsing this forum: No registered users and 8 guests